Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2021-3538 #578

Closed
womblep opened this issue Jan 7, 2025 · 9 comments
Closed

CVE-2021-3538 #578

womblep opened this issue Jan 7, 2025 · 9 comments

Comments

@womblep
Copy link

womblep commented Jan 7, 2025

Docker image on Docker Hub has a critical security defect CVE-2021-3538
There is a fixed Go UUID module, it probably just needs a refresh

Copy link

github-actions bot commented Jan 7, 2025

Your report is appreciated. Please star this repository to motivate its developers! ⭐

@adubovikov
Copy link
Member

Thank you! Fixed!

@womblep
Copy link
Author

womblep commented Jan 7, 2025

@adubovikov thank you so much!
Can you please push a new container version to docker hub?

@adubovikov
Copy link
Member

@lmangani can you please push ?

@adubovikov
Copy link
Member

@womblep it was pushed automaticaly! Please check

@womblep
Copy link
Author

womblep commented Jan 10, 2025

@adubovikov no, still seems to be the old version
image

@lmangani
Copy link
Member

lmangani commented Jan 10, 2025

@womblep our latest images are hosted on ghcr and that's what should be used
https://github.com/orgs/sipcapture/packages

What instructions are you following?

@womblep
Copy link
Author

womblep commented Jan 10, 2025

@lmangani I went here https://github.com/sipcapture/homer/wiki/Quick-Install#-docker-install and used the docker compose here https://github.com/sipcapture/homer7-docker/blob/7.7/heplify-server/hom7-prom-all/docker-compose.yml . All the images are pulled from Docker Hub, I didn't realise the newest ones were on ghcr.io
It might be worth changing that docker compose and noting that in the documentation.

@lmangani
Copy link
Member

That's indeed on us - we need to update all guides/docs, assigned to the team

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants